Created on
‎11-05-2025
08:59 AM
Edited on
‎12-08-2025
11:07 PM
By
Anthony_E
| Description |
This article describes a situation where a FortiGate forwards NetBIOS broadcast packets even though NetBIOS forwarding is disabled on the interface. |
| Scope | FortiGate running v7.0.16, v7.2.10, v7.4.4, and later builds. |
| Solution |
When the source IP address of the NetBIOS broadcast belongs to a different subnet than the FortiGate interface, the FortiGate does not recognize the packets as NetBIOS traffic.
Example configuration:
Example output:
As shown above, even though the netbios-forward is disabled, the NetBIOS UDP broadcast packets are forwarded out of the same interface because the traffic is redirected under allow-traffic-redirect.
Behavior by FortiOS version: FortiOS v7.0.16/v7.2.10/v7.4.4 and later:
Earlier FortiOS versions:
Workaround: Disable traffic redirection globally:
This issue has been resolved in v8.0.0 (scheduled to be released in March 2026). These timelines for firmware release are estimated and may be subject to change.
Note: v5.0 up to v7.0 are out of engineering support. So these commands might be different on higher versions. Consider upgrading the firmware level on the device to a supported version (v7.2 up to v7.6). Check the firmware path and compatibility depending on the hardware on the following link: Upgrade tool
Related article: Technical Tip: Traffic handled by FortiGate for packets with ingress & egress as same interface |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.